Hangover is a cyberespionage threat group active since at least 2013 and commonly associated with India. It is also tracked as Neon, Viceroy Tiger, and MONSOON. The group has conducted targeted intrusions primarily against government and military organizations in South Asia, with additional reported activity affecting a telecommunications target in Norway and indicators of operations involving Pakistan, China, the United States, and parts of Europe. Hangover is known for spear-phishing-led initial access using topical regional news themes and weaponized Microsoft Office documents. Its delivery tradecraft has evolved over time from simpler embedded code and links to more layered infection chains involving encoded content, embedded executables, archive-packaged components, and staged retrieval of payloads from attacker-controlled infrastructure. The group has used compromised third-party infrastructure in support of delivery operations. A malware family associated with Hangover is BackConfig, used to establish backdoor access for espionage and potential theft of sensitive information. BackConfig deployment has been described as multi-stage and designed to frustrate automated analysis, using scripting, scheduled tasks, conditional trigger mechanisms, and obfuscation. Once installed, the malware communicates over HTTPS and supports flexible post-compromise activity depending on deployed plugins and victim environment. Hangover has also been linked to PlugX-related activity through clustering research that equated the WS PlugX group with Hangover. PlugX capabilities observed in related activity include remote access, keylogging, screenshots, remote shell access, scanning, and other post-compromise functions, although such tooling may reflect shared malware ecosystem usage rather than a unique Hangover-exclusive platform. Overall, Hangover is best characterized as a targeted espionage actor focused on politically and strategically relevant entities, especially in South Asia, using phishing, staged malware delivery, stealthy persistence mechanisms, and encrypted command-and-control to support intelligence collection.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
14 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cyberespionage activity primarily targeting government and military organizations in South Asia via spear-phishing lures and weaponized Microsoft Office documents to install the BackConfig backdoor for follow-on espionage and potential data exfiltration.
Assessed in the presentation as equivalent to the PlugX WS group.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.